
slides
CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

Python Command-Line Ghidra Decompiler

MCP server plugin for JEB Pro that enables AI-assisted decompilation, method/field inspection, and automated renaming during APK reverse engineering.

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Curated Ghidra scripts to automate reverse engineering and vulnerability analysis: locate insecure functions, extract decompiler pseudocode, fix…

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.


Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

Static code analysis plugin for Android project. (Checkstyle, PMD)

Web-based Source Code Vulnerability Scanner

Easy setup of static analysis tools for Android and Java projects.